Trust
GDPR and data handling
What we hold, why we hold it, how long it stays, how your own contacts are treated, and how to get any of it exported or deleted. The legal instrument is the privacy policy; this page says the same thing in language you can act on.
Last updated
The short version
You own your data and the people on your list. We hold it to run the service you bought, keep it while your account is open, and delete it within 30 days of a verified request. Opt-out records survive deletion on purpose. The full compliance posture, the signed data processing agreement and the published subprocessor list live in the trust centre, and this page is the plain-language companion to them.
Who is the controller and who is the processor
You are the controller of your contacts. You decide who goes on the list, why they are being messaged, and what the message says. Blue Reacher is the processor: we hold and transmit that data on your instructions to run the service you bought, and we do not message your contacts for our own purposes or sell, rent or share your list with anyone. For the data we hold about you as a customer, meaning your account, your billing and your use of the platform, we are the controller and the answers below are ours.
That split decides who answers what. A request about a message someone received goes to the business that sent it. A request about a Blue Reacher account goes to us. Either way, write to support@bluereacher.com and we will tell you which one you have.
What data does Blue Reacher hold?
Six categories, and nothing outside them. Each row says what it is and the reason it exists, because a category with no stated purpose is the part of a privacy page nobody can check.
- Account and billing
- The name, work email, phone number and company details of the people who use the account, plus the billing record for the subscription. Held so the account exists, so we can reach you, and so invoices are correct.
- Contacts you upload
- The names, phone numbers and record fields of the people your team messages, as they arrive from your CRM or an upload. Held because they are the addressees of the messages you asked us to send.
- Message content and threads
- The messages sent and received on your lines, with timestamps, delivery states and which channel carried each one. Held so your team can read the conversation, so replies post back to your CRM, and so a delivery dispute can be answered with a record.
- Opt-outs and suppression
- Who asked not to be contacted, the exact text that triggered it, when, and every blocked attempt afterwards. Held because it is the only thing that stops a suppressed person from being messaged again, and because it is the record a compliance review asks for.
- Usage and technical logs
- IP address, browser and device type, pages visited, access times and activity logs from using the platform and this site. Held for security, troubleshooting and understanding what people actually use.
- Support correspondence
- What you wrote to us and what we wrote back. Held so a later conversation does not start from nothing.
How is your own contacts' data handled?
Their data is yours, held on your instructions, and used for nothing else. It is not pooled with other customers, not used to train anything, not sold, and not messaged by us. Workspaces are isolated from one another, traffic is encrypted in transit, and production access is limited to the people who operate the platform. The one thing we do to a contact without being asked is stop messaging them: an opt-out is detected on the reply, honored in seconds, and applied across every line, campaign and automation on the account, including manual sends from a rep who never saw the thread.
What stays with you: the lawful basis for messaging each contact, the consent record behind it, telling your contacts what you collect and why, and answering their requests as the controller. The anti-spam and acceptable use policy sets out the list practices we expect and the programs we refuse to run, and the security page states the practices in the same words we use with reviewers.
How long is data kept?
A rule rather than one number, because the categories genuinely differ and a single figure would be wrong for most of them.
- While the account is open
- Contacts, message threads, delivery records and usage data stay available, because a sales team needs its own conversation history to work.
- On deletion or account closure
- Account data, contacts and message content are removed from live systems within 30 days of a verified request. Backups roll off on their own cycle and are never restored to bring deleted data back.
- Kept on purpose after deletion
- Opt-out and suppression records, in the minimum form that identifies a number as do-not-contact. Erasing them would silently re-enable messaging to the exact people who asked to be left alone, which is the opposite of what an erasure request is for.
- Kept as long as law requires
- Invoices, payment records and the tax documentation attached to them, for the retention period the applicable accounting and tax rules set.
What rights do you have, and how do you use them?
If you are in the EU or the UK these come from GDPR. California residents get the equivalent set under CCPA, and several other US states now match it. We apply them to everyone who asks, wherever they live, because running two standards is how the wrong one gets applied. Every one of them starts with an email to support@bluereacher.com, and we answer within 30 days.
- Access
- Ask what we hold about you and get it, in a form you can read.
- Portability
- Ask for a machine-readable export you can load into another system.
- Rectification
- Ask us to correct anything wrong. Most account fields you can edit yourself; email for the rest.
- Erasure
- Ask us to delete it, subject to the suppression and legal-record exceptions above, which we name rather than hide.
- Restriction and objection
- Ask us to stop a particular processing activity, including marketing to you, while a question is being worked out.
- Complaint
- Take it to your supervisory authority. Using this page first is faster, but the right does not depend on us.
Deletion has its own page with the exact wording to send and what happens after: request a data deletion.
Compliance posture, stated exactly
Blue Reacher's controls are mapped to the SOC 2 Trust Services Criteria for security, availability and confidentiality. The control mapping, the DPA and the subprocessor list are published in the trust centre, where a reviewer can read them without asking. No authority issues a GDPR certificate, whatever a vendor page implies.
HIPAA works differently and is worth separating out. No authority issues a HIPAA certificate, and the thing that creates the obligation is a signed business associate agreement. Blue Reacher signs one on Enterprise plans, on top of encryption in transit and at rest, least-privilege access with audit logging, retention limits and verified deletion.
What a security review gets, without asking twice: the data processing agreement published in full rather than sent after an NDA, the subprocessor list published rather than offered on request, fifteen pre-answered review questions on the trust centre, the full control mapping, and a completed security questionnaire in your own format on request.
Who to contact
Every request in this page goes to support@bluereacher.com, which is read by the people who run the platform. Blue Reacher is operated by Sagency International LLC, United States. Put EXPORT, DELETE or GDPR in the subject and we will know what to do with it. If you would rather see your options laid out by what you need, the contact page routes each one.
Frequently asked questions
Is Blue Reacher GDPR compliant?
We operate to GDPR obligations and honor access, export, correction and deletion requests within the 30 days the regulation allows. Nobody issues a GDPR certificate, so any vendor claiming to be certified is describing something else. What you can check instead is the substance: the controller and processor split below, the categories of data we hold, how long we keep each one, and the address that actions a request.
Is Blue Reacher the controller or the processor of my contacts' data?
You are the controller of your contacts. You decide who is on the list, why they are being messaged and what is said. Blue Reacher is the processor: we hold and transmit that data on your instructions to run the service you bought. Consent, transparency and lawful basis for messaging your contacts are yours, and the platform enforces opt-outs mechanically on top of that.
What documentation does a security review get?
The published data processing agreement, the published subprocessor list, the full control mapping against the SOC 2 Trust Services Criteria, and a completed security questionnaire, all at bluereacher.com/trust. HIPAA obligations are created by a business associate agreement, which Blue Reacher signs on Enterprise plans.
How long do you keep my data?
Account and message data lives as long as the account does, because your team needs the thread history to work. When an account closes or you ask for deletion, it is removed from live systems within 30 days. Billing records are kept for the period tax and accounting law requires. Opt-out and suppression records are kept deliberately after deletion, because erasing them would allow the same person to be messaged again.
How do I get a copy of my data?
Email support@bluereacher.com from the address on the account, with EXPORT in the subject, and say which data you want. Account, contact and message data comes back in a machine-readable format you can load elsewhere, which is what portability under Article 20 means in practice. We answer inside 30 days and usually need one identity check first.
Someone messaged me using Blue Reacher. Who do I talk to?
The business that messaged you decides who is on its list, so it is the controller of your data and the first place to ask. You can also reply asking to stop, which suppresses you across that sender's entire account in seconds, and you can email support@bluereacher.com and we will route the request and act on our side as processor.
Where is data stored, and does it leave the EU?
Blue Reacher is operated from the United States by Sagency International LLC, and data processed by the platform and its service providers is handled there. For an EU or UK controller that is an international transfer, which needs the appropriate safeguards in your own record of processing. Ask us for the current subprocessor list before a review and we will send it.
This page describes how we handle data. It is not legal advice, and your own obligations as a controller are yours to take to counsel.